Debian DSA-2725-1 : tomcat6 - several vulnerabilities
Medium Nessus Plugin ID 68971
The remote Debian host is missing a security-related update.
Two security issues have been found in the Tomcat servlet and JSP engine : - CVE-2012-3544 The input filter for chunked transfer encodings could trigger high resource consumption through malformed CRLF sequences, resulting in denial of service. - CVE-2013-2067 The FormAuthenticator module was vulnerable to session fixation.
Upgrade the tomcat6 packages. For the oldstable distribution (squeeze), these problems have been fixed in version 6.0.35-1+squeeze3. This update also provides fixes for CVE-2012-2733, CVE-2012-3546, CVE-2012-4431, CVE-2012-4534, CVE-2012-5885, CVE-2012-5886 and CVE-2012-5887, which were all fixed for stable already. For the stable distribution (wheezy), these problems have been fixed in version 6.0.35-6+deb7u1.